← Back to outrayo.ravinaro.com

Privacy Policy

Last updated: September 8, 2026 · Draft for beta review — final version pending legal review.

1. Who we are

Outrayo ("we", "us") is operated by Ravinaro LLC-FZ. This policy covers the Outrayo platform at app.outrayo.ravinaro.com and the marketing site at outrayo.ravinaro.com.

2. What we process

  • Account data: your name, email, password (hashed), workspace details.
  • Connected mailboxes: OAuth tokens for Gmail/Microsoft accounts you explicitly connect, used only to send messages you approve and read replies to those messages.
  • Lead data: publicly available business information (company name, website content, published business contact emails) discovered from the open web at your direction, plus your communications with those leads.

3. Roles: controller vs processor

For your own account data, we are the controller. For lead data you discover and process through Outrayo, you are the controller and we act as processor: you choose who to contact, determine the lawful basis (our campaign tools require a jurisdiction attestation), and we process on your documented instructions.

4. How we use data

  • Operating the service (discovery, drafting, sending, tracking, attribution).
  • Protecting the platform and email ecosystem from abuse (rate limits, content screening, suppression lists).
  • Billing and service communication. We do not sell data, and we do not email your leads for our own marketing.

5. Subprocessors

We use third parties to operate the platform: Cloudflare (hosting, databases), Stripe (payments), the LLM/search/scraping/verification providers you or we configure (OpenAI/Anthropic or equivalent, Serper, Exa, Firecrawl, email verifiers), and Google/Microsoft APIs for mailbox access. The current list is available on request.

6. Your rights (and your leads' rights)

EU/UK users have GDPR rights including access, rectification, erasure, and portability. Outrayo provides built-in data-subject-request tooling so you (as controller) can fulfil requests relating to lead data — erasure requests propagate to suppression lists instantly. Contact [email protected] for anything about your own data.

7. Security & retention

OAuth tokens and secrets are encrypted at rest (AES-GCM). Data is stored in Cloudflare D1 with daily backups (30-day point-in-time recovery). EU-tenant data can be pinned to EU-resident storage. We delete account data within 30 days of verified account deletion.

8. Contact

Privacy questions: [email protected] · Ravinaro LLC-FZ.